Do not model the attacker

  • Authors:
  • Jan Meier

  • Affiliations:
  • Security in Distributed Applications, Hamburg University of Technology, Germany

  • Venue:
  • Security'08 Proceedings of the 16th International conference on Security protocols
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

We identify attacker modelling as major obstacle when searching for ways to defeat security protocols. For protocols verified to be secure, attacks are discovered. Since this problem is not limited to the Dolev-Yao attacker but applies to all modelled attackers, we propose a new approach. We argue that formal verification methods should be used to show the impact of analyst provided actions have on protocols. This approach frees verification tools from having to know all the actions an attacker could perform. We show the benefits of having both the security proof and an explicit list of considered actions. Implementers can easily determine if the protocol is suited for their application. Additionally, developers understand the requirements an implementation has to fulfil. Lastly, our approach allows proofs to be adapted to new environments without changing the verification tool.